Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Symantec's Ramzan on solving the antivirus puzzle
Search Topic:
Uniqs:
173
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
JRB2 HAPPY BIRTHDAY »
« New security settings in IE8  
AuthorAll Replies


Stem Bolt
Premium
join:2002-11-08
Cleveland, OH

Symantec's Ramzan on solving the antivirus puzzle

»news.cnet.com/8301-1009_3-10278426-83.html
quote:
What are the main challenges with blocking viruses and spam?

Ramzan: One of biggest challenges overall is that these things are rapidly evolving. We're seeing variations upon variation of various types of malware and viruses. The traditional approach of trying to use a signature-based detection to detect that this part file is good or bad is going to be limited. Signatures were very good 10 years ago when there were a small number of samples out there that were on a large number of machines. Nowadays, when you have essentially micro-distribution of a large number of threats, where maybe there are millions and millions of threats out there and each is on only a few machines, having a signature to try to protect against those threats doesn't work as well. That's because you're only protecting a few users at once with a given signature. It doesn't scale nicely. With reputation-based protection, we look at not only what the software is doing, but we might know that this application is only on five machines in the world. That's something we can monitor very easily. Whereas before the attacker would try to be the needle in a haystack and hide...we now have a very powerful magnet so we can find those needles effortlessly.

So is signature-based antivirus protection dead?

Ramzan: No, not at all. I think that signatures are very useful, but in a certain context. There are still threats out there that do get to a large number of machines. For example, we've seen the Conficker, or Downadup worm come out recently. That's a classic example of a threat that makes sense to protect with signatures. Signatures are simple, they're easy to compute, they've been around for a long time. They have their uses, but they only protect you against one spectrum or one part of the spectrum of possible threats out there.
--
Norton 2010 BETA + Online Armor Free + Router/SPI
-
Forums » Up and Running » Security » Security JRB2 HAPPY BIRTHDAY »
« New security settings in IE8  


Sunday, 29-Nov 01:49:03 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [122] Time Warner Cable Fires Broadside At Broadcasters
· [112] New AT&T Ad Campaign Hits Back At Verizon
· [96] Apple Joins AT&T Verizon Snark Fest
· [87] New Bill Takes Aim At Higher Verizon ETFs
· [80] TiVo Sees Record Customer Losses
· [73] Weekend Open Thread
· [70] Verizon CEO: Hulu Will Be Dead Soon
· [69] In-Flight Internet Headed For Bumpy Landing?
· [62] Thanksgiving Open Thread
· [40] EFF Wages War On Fine Print
Most people now reading
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· [ PVP] 3.2 DK PvP D/W Spec... [World of Warcraft]
· Using AirMax to provide triple play services? [Wireless Service Providers]
· Windows 7 boot manager editing questions [Microsoft Help]
· sysguard2010.com [Security]
· [FREEZING] Spybost S&D Updater [Security]
· Level requirement for Northrend [World of Warcraft]
· [ Classes] Druid tanking: rotation and glyphs [World of Warcraft]
· [ fiber tech] best router for FiOS [Verizon Fiber Optics]